Andrew van der Stock

CEO

Geelong, Victoria, Australia34 yrs 4 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Executive Director at OWASP leading global application security.
  • Co-lead for OWASP Top 10 and Application Security Verification Standard.
  • Over 25 years of experience in IT and security.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in application security and organizational leadership.

Contact

Skills

Core Skills

Application SecuritySecurity Architecture DesignProject ManagementComplianceGovernanceLeadershipCommunity EngagementTechnical WritingOrganizational DevelopmentTechnical LeadershipService DevelopmentClient EngagementSecurity ArchitectureWeb Application SecuritySecure DevelopmentSecurity UpdatesIt InfrastructureSystem AdministrationTutoringQuality AssuranceWeb DevelopmentProgramming

Other Skills

Agile MethodologiesAgile SecurityArchitectureArchitecturesBusiness ContinuityCOBITChapter DevelopmentCloud SecurityCode ReviewComputer ForensicsComputer SecurityContent DevelopmentCourse DevelopmentCryptographyData Analysis

About

NOTE: I do not monitor my Linked In regularly. Please email me if you need to contact me. Andrew is a seasoned web application security specialist and enterprise security architect. He is the Executive Director at OWASP, taking the Foundation through organizational change and taking our mission to the next level. Andrew has worked in the IT industry for over 25 years. Andrew has researched and developed the web application security and architecture fields since 1998. He is a Lifetime member of OWASP, former Director, and co-leads the OWASP Application Security Verification Standard and OWASP Top 10 projects. An Australian ex-pat of Melbourne and Sydney, he currently lives in the USA with his family.

Experience

34 yrs 4 mos
Total Experience
3 yrs 6 mos
Average Tenure
5 yrs 10 mos
Current Experience

Owasp foundation

6 roles

Executive Director

Promoted

Jun 2020Present · 5 yrs 10 mos

  • As Executive Director, Andrew will be leading the organization to improve application security globally, broaden the inclusiveness of our mission to bring together developers, testers, and security professionals. The organization has historically been driven by a number of global events, but with COVID 19, it will be necessary to broaden our income sources and activities to help deliver industry leading updates to all our major projects, a transition to virtual training and conferences, and help drive membership and chapter growth.
Application SecuritySecurity Architecture DesignOrganizational Change

Project Lead, OWASP Top 10

May 2017Present · 8 yrs 11 mos

  • As project co-lead, Andrew was instrumental in rebooting the OWASP Top 10 2017, and getting it out the door. Appointing three other co-leads, and working with OWASP members and the wider industry, Andrew helped define a new transparent development and release process, and worked tirelessly to get new data collected, analyzed, and re-wrote the OWASP Top 10 2017. We are kicked off the OWASP Top 10 2020 in August 2019, with a likely release date of Q3 2020.
Application SecurityProject ManagementData Analysis

Director, Global Board

Promoted

Jan 2015Dec 2018 · 3 yrs 11 mos

  • Andrew was elected to the Global Board of Directors for 2015-2016, standing on a platform of being an OWASP project champion, improving diversity and inclusion in application security, building open source university level curriculums for adoption worldwide, and improving OWASP's transparency, governance and leadership.
GovernanceDiversity and InclusionLeadership

Project Lead, OWASP Developer Guide

Promoted

Apr 2012May 2015 · 3 yrs 1 mo

  • The OWASP Developer Guide is the Web Application Security Bible.
  • Andrew is leading a team of experts in updating the content to include modern concerns, whilst ensuring the fundamentals are robust, easily understood, implementable, and testable.
Content DevelopmentApplication Security

Committee Member, Global Chapters Committee

Dec 2010Jan 2012 · 1 yr 1 mo

  • General agent of havoc and change. Working to make chapters better throughout the world.
Chapter DevelopmentCommunity Engagement

Project co-lead, OWASP Application Security Verification Standard

Feb 2009Present · 17 yrs 2 mos

  • Andrew has participated in the OWASP Application Security Verification Standard since the release of 1.0. He was the co-lead of 2.0, 3.0 and 4.0. The OWASP Application Security Verification Standard is the premier and most comprehensive application security standard, used by governments and large organizations all over the globe. If you are looking for an AppSec standard, this is it. It's designed to be testable, with simple requirements. 4.0 incorporates NIST 800-63 compliance and more than covers the OWASP Top 10 2017.
Application SecurityStandard DevelopmentCompliance

Synopsys inc

Managed Services Technical Leader, Senior Principal Consultant

Jun 2017May 2020 · 2 yrs 11 mos · Colorado Springs, Colorado Area

  • I provide technical leadership to a growing and vibrant global team located in Bangalore, India, Bloomington Indiana, Sterling Virginia, and across the United States. Andrew is responsible for providing global Technical Leadership, working with Practice Directors to update and define new services, revamp existing services to be the very definition of industry-leading, work with our clients and internal teams to build custom managed security testing solutions, communicate publicly on important topics, and to ensure that our staff have the best training and opportunities to progress to the next level.
Technical LeadershipService Development

Threat intelligence pty ltd

CTO

Nov 2014Jun 2017 · 2 yrs 7 mos · Australia

  • As Chief Technology Officer, I am helping build out Threat Intelligence's portfolio of services, defining agile delivery of modern services that global clients need.
  • My background is secure code review and security architecture, so no guesses as to what I do during the day. Whilst we move our clients to be far ahead of the pack by thinking differently about security, we will still be doing penetration testing and vulnerability assessments, but our goal is to create a fundamental shift in the security mindset from reactive and tick box compliance to proactive security that actually reduces the risks from threats. This means working closely with our clients, going on a shared security journey, and measuring progress.
  • As we grow, my goal is to make Threat Intelligence the first choice for out of the box thinkers - whether grads through hardened cynics - to want to come work for us, learn from us, and develop their careers as professional security consultants. Too many boutiques and large consulting firms talk the talk during recruitment but then don't follow through. We want a different company culture that respects the unusual qualities that infosec giants possess, and harness those attributes for high performing engagements and high quality deliverables every time for our clients.
Service DevelopmentAgile Methodologies

Kpmg australia

Associate Director

Jun 2011Nov 2014 · 3 yrs 5 mos · Melbourne, Australia

  • Andrew led a growing team of technical specialists within KPMG Australia, performing the sort of highly technical reviews you'd expect from a boutique consultancy, but with the aim of enabling secure business with the global backing of the entire KPMG team.
  • I mentored the entire Australian technical security services team, provided useful information and assistance to our global pen test community, and helped recruit the best and brightest to create the future of our industry.
  • I designed services to be delivered nationally by the best suited team members to meet our client's needs wherever they are located. The work plans are not secret or the dark arts - it's all documented in the open standards work I participate in at OWASP. The best results flow when we work closely with our clients.
  • The results have been nothing short of breathtaking - highly satisfied clients that leads directly to repeat business and word of mouth recommendations. Leading edge research and good recruiting and mentoring begets excellent work begets great security solutions for customers.
Technical LeadershipMentoring

Pure hacking

Principal Consultant

Jan 2009May 2011 · 2 yrs 4 mos

  • At Pure Hacking, I established the world's best security architecture, code review, and agile security program. Some of my wins included:
  • Agile Security Development Lifecycle Programs
  • Security Architecture
  • Security Architecture Reviews
  • Secure Code Reviews
  • and Penetration Testing
  • Andrew moved back to Australia to take up this position.
Service DesignClient Engagement

Aspect security

Senior Security Engineer

Nov 2006Jan 2009 · 2 yrs 2 mos

  • Consult to a wide variety of clients, primarily on web application security issues.
  • Conducted code reviews, vulnerability assessments, and risk management and architecture.
  • Travelled extensively and trained several hundred developers in the fine art of secure software development.
  • Created new training materials for Ajax and Web Services, and updated other training decks.
Security ArchitectureAgile Security

Owasp foundation

3 roles

Executive Director

Promoted

May 2006Nov 2007 · 1 yr 6 mos

  • Andrew worked to create the OWASP Board as it stands today. Andrew worked to create transparency and robust organizational processes.
Organizational DevelopmentTransparency

Project Co-Lead, OWASP Top 10 2007

Promoted

Mar 2006Nov 2007 · 1 yr 8 mos

  • Andrew was one of the primary forces behind the OWASP Top 10 2007, which defined the evidence based methodology used by the OWASP Top 10 for the next decade. The OWASP Top 10 2007 was incorporated into PCI DSS 1.0, which is the payments industry security standard as section 6.5.
Project ManagementSecurity Standards

Lead Author, OWASP Guide

Jan 2002Dec 2009 · 7 yrs 11 mos

  • Contributor 2002-2004
  • Lead Author / Editor of Guide 2.0 (from November 2004 on)
  • Currently working on Guide 3.0
Content DevelopmentTechnical Writing

National australia bank

Web Application Security Specialist

Jan 2005Nov 2006 · 1 yr 10 mos

  • Provide code reviews to many internal clients. Currently working on security architecture for a forthcoming large scale corporate Internet Banking product.
Secure DevelopmentCode Review

Ultimabb

Lead Developer

Dec 2004Jan 2009 · 4 yrs 1 mo

  • Re-writing a secure forum, initially based on XMB Forum's code base, but now has less than 10% of the original code.
  • As Security Manager I ensure the code is safe to run in hostile environments, track Bugtraq and develop fixes for known issues
  • As this is an open source project conducted in my own time, it's going fairly slowly and may never complete.
Web Application SecurityTraining

B-sec

Chief Technologist

Jan 2002Jan 2005 · 3 yrs

  • Security architecture and design, web application security reviews, threat risk assessments, forensic collection and analysis, and organization policy. Mentoring and training staff.
Code ReviewSecurity Architecture

Xmb

Developer

Jan 2002Dec 2004 · 2 yrs 11 mos

  • Provided security updates to XMB Forum
  • Developer (2003-2004)
Security ArchitectureForensics

Sage-au

El Presidente (retired)

Jan 2000Jan 2001 · 1 yr

  • Lead SAGE-AU.
Security ArchitectureForensics

E-secure

Senior Security Architect

Nov 1998Jan 2002 · 3 yrs 2 mos

  • Security architecture and design, web application security reviews, threat risk assessments, firewall and infrastructure design and implementation, and organization policy. Mentoring and training staff.
Security UpdatesDevelopment

E-secure pty ltd

Senior Security Architect

Jan 1998Jan 2001 · 3 yrs

  • Security architecture and design, web application security reviews, threat risk assessments, firewall and infrastructure design and implementation, and organization policy. Mentoring and training staff

North western health

Senior System Administrator

Jul 1997Nov 1998 · 1 yr 4 mos

  • Andrew was employed to undertake a transformation of disparate hospital systems across a wide range of previous health care networks, and to bring the benefits of a large centrally managed IT systems infrastructure to improve patient care and privacy. Andrew designed and implemented new IT infrastructure, undertaking a competitive request for proposals that led to the acquisition of a large mainframe to run the PICK based patient electronic record management system, and other large IT projects, such as Y2K and a relocation of many sub-standard server closets to a purpose built data center.
Security ArchitectureForensics

St vincents hospital

Senior System Administrator

Jan 1996Jul 1997 · 1 yr 6 mos

  • In this role, Andrew was initially employed as a Microsoft Windows system administrator and Macintosh help desk resource, but was quickly identified to work on major IT transformation projects, such as the roll out of Microsoft Exchange replacing a hodge podge of Lotus ccMail and MS Mail. Andrew rose to become a senior systems administrator for St Vincent's Hospital. One of Andrew's key achievements was getting St Vincent's on the Internet, and establishing the firewall, website and DMZ during a time when hospitals rarely had e-mail, let alone a web presence.
IT InfrastructureProject Management

Rmit

2 roles

Tutor

Mar 1995Nov 1995 · 8 mos

  • Tutored Internet subjects to MBA students. Constructed the course syllabus and provided four hours a week contact with several classes.
System Administration

System Administrator

Jan 1995Jan 1996 · 1 yr

  • System administrator for the Business Faculty.
System AdministrationIT Transformation

Nemostar

2 roles

Software Quality Assurance

Promoted

Dec 1994Jul 1995 · 7 mos

  • Provided part time SQA services to Nemostar on a product called Flexifax.
TutoringCourse Development

Lead Programmer, MacOS port

Sep 1993Jul 1994 · 10 mos

  • Worked on porting a Win16 program to MacOS.
Web Development

Melbourne university

Project Worker

Feb 1994Nov 1994 · 9 mos

  • Provided web server and site design for an early outreach program for youths. Duties included obtaining funding from likely donor organizations.
Quality Assurance

Connecting point

Help Desk and System Administrator

Nov 1991Nov 1993 · 2 yrs

  • Worked as a help desk drone for Mac products. Helped (or hindered as the case may be) with system administration.
Programming

Education

RMIT University

CS — Computer Science

Jan 1990Jan 1994

Melbourne High School

HSC

Feb 1985Nov 1988

Stackforce found 100+ more professionals with Application Security & Security Architecture Design

Explore similar profiles based on matching skills and experience